First published: Thu Sep 01 2022(Updated: )
Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3.
Credit: security@apache.org security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache ShenYu | =2.4.2 | |
Apache ShenYu | =2.4.3 | |
maven/org.apache.shenyu:shenyu-common | >=2.4.2<=2.4.3 | 2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Apache ShenYu Admin is CVE-2022-37435.
The severity rating for CVE-2022-37435 is high.
CVE-2022-37435 allows low-privilege administrators to modify high-privilege administrator's passwords in Apache ShenYu Admin.
Versions 2.4.2 and 2.4.3 of Apache ShenYu are affected by CVE-2022-37435.
Upgrade to version 2.5.0 of Apache ShenYu which contains a patch for CVE-2022-37435.